Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Monday, 19 March 2012

Online banking: Is your money safe from hackers?

By Marcie Geffner | Bankrate.com
When you log in to your online banking account, you presumably know that you are yourself. But how does your bank know you're you and not an unauthorized family member, friend or hacker trying to gain access to your account?
The answer involves something called authentication technology, or methods to identify a computer's user, and it's about to get more sophisticated thanks to new federal guidelines that require banks to be more diligent about their online banking security.
Most of the changes will happen behind the scenes, but bank customers might notice a few tweaks as well, according to Cary Whaley, vice president of payment and technology policy at Independent Community Bankers of America, a banking industry group in Washington, D.C.
"Consumers have to be sensitive, and I think they are, to the fact that banks are extremely concerned with making sure it's them doing the transaction and not somebody else," he says.

Real risk

The new guidelines for banks were issued in June 2011 as a supplement to regulations originally promulgated seven years ago by the Federal Financial Institutions Examination Council, or FFIEC, an interagency group that prescribes uniform principals, standards and reports for federal bank examiners.
According to "Supplement to Authentication in an Internet Banking Environment," a FFIEC document, the new guidelines include the following.
  • Reinforce expectations that financial institutions should perform periodic risk assessments.
  • Identify controls that are now less effective, given that the online banking environment has become more "hostile," to use the FFIEC's description.
  • Identify minimum elements that should be part of banks' consumer awareness and education efforts about banking online.
The risks of online banking fraud are real. More people are using these services. And more online fraudsters are using more sophisticated, effective and malicious methods to perpetrate their crimes, the FFIEC says. Organized criminal groups have been identified as well, and some now specialize in financial fraud, using kits of automated "attack tools" that can be downloaded from the Internet.
Banks that make substantive changes to their security protocols may send new terms to their customers, Whaley says.
That will create opportunities for both customer education and fraud, the FDIC says. The concern arises because scammers took advantage of the original guidance issued in 2005 to try to trick bank customers into "enrolling" in new security measures.

Simple isn't sufficient

Banks have used simple identification technologies, such as usernames, passwords and computer cookies (small files that websites store on users' computers for identification purposes), for many years. But now more sophisticated techniques are expected to be employed for banking online, Whaley says.
"Simple authentication -- a password and username -- is just not sufficient enough to protect," Whaley says. "That's a good starting point, but you need more."
Among other possibilities, the newer techniques are likely to include the following.
  • Complex device identification such as PC configuration (how a computer is set up), Internet Protocol, or IP, address (a unique number that identifies each computer connected to the Internet) or geolocation (the identification of a device's physical whereabouts in the real world).
  • Challenge questions for which the answers can't easily be found online through Google or social media.
  • Nonsensical questions designed to confuse anyone other than the authorized user.

Consumer tips

Implementation of enhanced controls should make online banking more secure, according to Greg Hernandez, a spokesman for the Federal Deposit Insurance Corp. in Washington, D.C.
Still, Hernandez says most unauthorized bank account access occurs not as a result of a weakness in the bank's security system but due to malware, or malicious software, installed on the consumer's computer.
That means consumers shouldn't rely solely on the bank's technology but also be vigilant on their own when banking online to ward off financial cyber crimes.
"The most important thing consumers can do to protect themselves is to practice safe computing at home," Hernandez says. "They should use a firewall and anti-virus/anti-malware software and keep it updated. They should be on the lookout for suspicious emails and avoid suspicious websites. They should not click on links contained in suspicious emails or download software from questionable sources."

Friday, 9 March 2012

Helping hackers don white hats

 The FBI warns that cyberspace hacking may soon surpass terrorism as a threat. But many hackers easily give up and become useful 'white hat' security experts. Are there better ways to win over more of them?
By the Monitor's Editorial Board / March 8, 2012
Protestors wearing Guy Fawks masks hold the logos of the international hacker group Anonymous during a protest against the Anti-Counterfeiting Trade Agreement in Budapest, Hungary. The shadowy world of Internet hackers and pranksters was rocked by news March 6 that Hector Xavier Monsegur, one of the world’s most-wanted computer vandals has been an FBI informant for months.
Janos Marjai/MTI/AP Photo
Enlarge
In the near future, warned FBI Director Robert Mueller last week, threats against computer networks and other parts of cyberspace will be the No. 1 security danger in the United States – surpassing terrorism.

His words echo those of Leon Panetta, the Defense secretary, who last year said “the next Pearl Harbor” could be a cyberattack on government security systems or the nation’s electricity grid.
Such alerts to the growing problem of criminal or state-sponsored hacking have pushed both private firms and the government to spend billions on computer defenses like Internet firewalls.
RELATED: A cascade of Internet events
But they’ve also led to a hiring of hackers who have been caught or repented. The idea is as simple as “it takes a thief to catch a thief,” but it is especially true in the complex world of botnets and other dark arts of digital crime.
Many companies and even the military say they need the best software workers to defend their systems, and often the solution is to employ a former “black hat” hacker who has decided to be a “white hat” (or ethical) hacker.
“If they [hackers] have been slightly naughty boys, very often they enjoy stopping other naughty boys,” said Lord West, Britain’s first cybersecurity minister, a few years ago when he began to recruit former hackers to defend national electronic security.
In his speech last week, Mr. Mueller advised US companies to focus not only on reducing their vulnerability to attacks with defensive technologies but also to develop ways “to catch threat actors.”
One example of that more aggressive approach is the news this week that a leading member of the “hactivist” group Lulz Security, which is an offshoot of Anonymous, pleaded guilty to dozens of hacking charges. Hector Xavier Monsegur was caught last year in New York and has since helped law enforcement officials find and arrest other hackers.
The fact that so many hackers have turned to white-hat security work shows the need to better understand their motives so as to better catch or entice them to give up their hacking. Many of them are very smart young men or boys as young as 15 who are social misfits and who start out hacking for the thrill. Not all want money. Many say they oppose secrecy or believe in helping people download copyrighted movies and music free of charge. 
One famous former hacker, Michael Calce (a.k.a. Mafiaboy), told Canadian television: “I realize what I did was wrong, and I feel bad about it, and I think I can help people with it by sharing my experiences.”
Fear of being caught may be the most obvious reason for a hacker to quit. But with so many hackers in their teens, law enforcement and others should be able to find nonpunitive ways to reach them.
A whole generation is now glued to digital devices, making the need even greater for a proactive way to prevent young people from becoming hackers or to spot them early on.